The Ryuk ransomware operators have organized one of the most prevalent threat groups over the past year. Recent research shows how their methods are advancing.

The operators showed preference to hosts with exposed remote desktop connections by using phishing emails as an initial entry to deliver their malware. To find and exploit these exposed RDP hosts, Ryuk operators are using brute force and spray and pray tactics. They have also been observed using the BazaCall campaign to spread malware through call centers where targeted entities are directed to open excel documents containing malware.

Ryuk’s operators then conduct reconnaissance in two different phases. First to find out where the most valuable data and information is located within a compromised environment. Secondly, they find out the yearly revenue of their victim to ensure the ransom demand they request is feasible for the particular organization. Further steps involve using Cobalt Strike to expose general antivirus and endpoint detection and response tools to aide Ryuk in evading them.

More recent techniques show the operators utilizing KeeThief which is an open-source tool that can extract credentials from password managers. KeeThief extracts vital information from the memory of a running process with an unlocked database. When they are able to obtain the credentials of local administrators, they can work their way around defenses controlled by those administrators.


